Welcome! Register for a free account (or login) > How does it work?
|
|


Feb 9 2010, 11:10 AM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 23 Joined: 2-February 10 Member No.: 90,500 Operating System: WIN XP PRO WIN 7PRO |
I am new to this, so please be patient. Before Christmas, everything seamed to be ok. On Christmas the antivirus software stopped updating on 2 computers and I could not get it going on either one. I removed it on both. Then I could not get it installed on either. Mcafee virtual tech crashed on both. I noticed for the first time that CHKDSK was giving errors on both machines that I have never seen on either machine before. Mcafee support cleaned the computer, but could not get their software to install. They blamed Microsoft. Microsoft could not resolve the problems and blamed the drivers. The drivers were the latest and not corrupted and simultaneous failure of the hardware was blamed. Since then I have tested memory and harddrives without any failures and I had the test computer independently tested to verify it was without error.
I noticed that the CHKDSK errors that only occurred on the boot drives and did not resolve with CHKDSK /F on boot, stop when I disconnected the computer from the internet. I restriped, low format, verify, mount the largest of the offered partitions, format it and reload XP PRO from scratch. I noticed that the computer had already had in it the name of my active workgroup and I did not have to type over the default "workgroup" as I had to do on all previous reloads of XP PRO. I manually check firewall and check to make sure it is installed. In the hour that it was taking to activate XP PRO I rechecked the firewall and it had been disabled and CHKDSK was giving errors. I disconnected from the internet and repeated the process reconnected and ran your tests. Am I clean? Thank you and if I am clean, what do I do with the other computers? For completeness CHKDSK gives errors on this computer with Windows Essentials disabled and connected to the internet. They stop when I pull the plug from the internet. They did not start until I loaded Windows Essentials on this computer and it was running. After it completed its first clean scan and posted its results, it kept consuming 50% of the processor and I got the first CHKDSK errors at that time. Windows Essentials was not installed on either computer when the problems started. defogger_disable by jpshortstuff (29.01.10.1) Log created at 09:27 on 09/02/2010 (DAV34) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=-GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-02-09 10:10:50 Windows 5.1.2600 Service Pack 3 Running: 5t4cqdmg.exe; Driver: C:\DOCUME~1\DAV34\LOCALS~1\Temp\pxtdapob.sys ---- Kernel code sections - GMER 1.0.15 ---- init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xBA9F6510] ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) ---- EOF - GMER 1.0.15 ---- UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 2/7/2010 10:07:19 AM System Uptime: 2/9/2010 8:56:59 AM (2 hours ago) Motherboard: Gigabyte Technology Co., Ltd. | | 8KNXPU64 Processor: Intel® Pentium® 4 CPU 3.40GHz | Socket 478 | 3407/200mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 68 GiB total, 60.786 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Universal Serial Bus (USB) Controller Device ID: PCI\VEN_8086&DEV_25AD&SUBSYS_50061458&REV_02\3&13C0B0C5&0&EF Manufacturer: Name: Universal Serial Bus (USB) Controller PNP Device ID: PCI\VEN_8086&DEV_25AD&SUBSYS_50061458&REV_02\3&13C0B0C5&0&EF Service: Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Universal Serial Bus (USB) Controller Device ID: PCI\VEN_1106&DEV_3104&SUBSYS_12340925&REV_51\4&2BA57D2F&0&5AF0 Manufacturer: Name: Universal Serial Bus (USB) Controller PNP Device ID: PCI\VEN_1106&DEV_3104&SUBSYS_12340925&REV_51\4&2BA57D2F&0&5AF0 Service: ==== System Restore Points =================== RP1: 2/7/2010 10:19:15 AM - System Checkpoint RP2: 2/7/2010 11:05:05 AM - Installed DirectX 9.0 RP3: 2/7/2010 11:12:32 AM - Installed TEG-PCITXR 32bit Gigabit PCI Adatper RP4: 2/7/2010 11:29:33 AM - Software Distribution Service 3.0 RP5: 2/7/2010 11:29:35 AM - Installed Windows XP KB842773. RP6: 2/7/2010 11:29:53 AM - Installed Windows XP KB892130. RP7: 2/7/2010 11:42:08 AM - Software Distribution Service 3.0 RP8: 2/7/2010 11:45:12 AM - Installed Windows XP Service Pack 2. RP9: 2/7/2010 11:55:28 AM - Software Distribution Service 3.0 RP10: 2/7/2010 12:14:09 PM - Software Distribution Service 3.0 RP11: 2/7/2010 12:36:07 PM - Installed Windows XP WgaNotify. RP12: 2/7/2010 12:38:41 PM - Software Distribution Service 3.0 RP13: 2/7/2010 1:03:11 PM - Software Distribution Service 3.0 RP14: 2/7/2010 1:20:42 PM - Software Distribution Service 3.0 RP15: 2/9/2010 9:07:53 AM - Software Distribution Service 3.0 ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver ATI HydraVision Enable S3 for USB Device ERUNT 1.1j Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB976098-v2) Intel® PRO Network Adapters and Drivers Intel® PROSet Malwarebytes' Anti-Malware Microsoft Antimalware Microsoft Application Error Reporting Microsoft Security Essentials Realtek AC'97 Audio Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) TEG-PCITXR 32bit Gigabit PCI Adatper Update for Windows Internet Explorer 8 (KB978506) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB978207) WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows XP Service Pack 3 ==== Event Viewer Messages From Past Week ======== 2/9/2010 10:14:23 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the SamSs service. 2/9/2010 10:13:53 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the ProtectedStorage service. 2/7/2010 11:22:00 AM, error: NetBT [4311] - Initialization failed because the driver device could not be created. 2/7/2010 10:19:16 AM, error: System Error [1003] - Error code 000000d1, parameter1 00000002, parameter2 00000007, parameter3 00000001, parameter4 f77f0001. ==== End Of File =========================== DDS (Ver_09-06-26.01) - NTFSx86 Run by DAV34 at 10:13:19.84 on Tue 02/09/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1510 [GMT -6:00] AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF} ============== Running Processes =============== C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Essentials\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Microsoft Security Essentials\msseces.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\d\dds.scr ============== Pseudo HJT Report =============== EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [PRONoMgr.exe] c:\program files\intel\ncs\proset\PRONoMgr.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide StartupFolder: c:\docume~1\dav34\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1265563673841 DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Notify: AtiExtEvent - Ati2evxx.dll ============= SERVICES / DRIVERS =============== R0 a320raid;a320raid;c:\windows\system32\drivers\a320raid.sys [2004-8-6 242130] =============== Created Last 30 ================ 2010-02-09 08:58 274,288 a------- c:\windows\system32\mucltui.dll 2010-02-09 08:58 215,920 a------- c:\windows\system32\muweb.dll 2010-02-09 08:58 16,736 a------- c:\windows\system32\mucltui.dll.mui 2010-02-07 13:52 <DIR> --d----- c:\docume~1\dav34\applic~1\Malwarebytes 2010-02-07 13:52 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-07 13:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-02-07 13:52 19,160 a------- c:\windows\system32\drivers\mbam.sys 2010-02-07 13:52 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware 2010-02-07 13:20 181,120 -------- c:\windows\system32\MpSigStub.exe 2010-02-07 13:18 <DIR> --d----- c:\program files\Microsoft Security Essentials 2010-02-07 13:16 <DIR> --d----- C:\d 2010-02-07 12:59 <DIR> --dsh--- c:\documents and settings\dav34\IECompatCache 2010-02-07 12:59 <DIR> --dsh--- c:\documents and settings\dav34\PrivacIE 2010-02-07 12:43 <DIR> --d----- c:\windows\system32\scripting 2010-02-07 12:43 <DIR> --d----- c:\windows\system32\en 2010-02-07 12:43 <DIR> --d----- c:\windows\l2schemas 2010-02-07 12:42 <DIR> --d----- c:\windows\network diagnostic 2010-02-07 12:34 <DIR> --dsh--- c:\documents and settings\dav34\IETldCache 2010-02-07 12:30 69,120 -c------ c:\windows\system32\dllcache\iecompat.dll 2010-02-07 12:30 <DIR> --d----- c:\windows\ie8updates 2010-02-07 12:30 11,070,464 -c------ c:\windows\system32\dllcache\ieframe.dll 2010-02-07 12:30 1,985,536 -c------ c:\windows\system32\dllcache\iertutil.dll 2010-02-07 12:30 594,432 -c------ c:\windows\system32\dllcache\msfeeds.dll 2010-02-07 12:30 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll 2010-02-07 12:30 55,296 -c------ c:\windows\system32\dllcache\msfeedsbs.dll 2010-02-07 12:30 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll 2010-02-07 12:30 <DIR> -cd-h--- c:\windows\ie8 2010-02-07 12:08 208,896 -c------ c:\windows\system32\dllcache\unregmp2.exe 2010-02-07 12:02 272,128 -c------ c:\windows\system32\dllcache\bthport.sys 2010-02-07 12:00 153,088 -c------ c:\windows\system32\dllcache\triedit.dll 2010-02-07 12:00 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx 2010-02-07 11:55 <DIR> --d----- c:\windows\system32\PreInstall 2010-02-07 11:55 <DIR> --d-h--- c:\windows\$hf_mig$ 2010-02-07 11:51 <DIR> --d----- c:\windows\system32\wbem\AutoRecover 2010-02-07 11:47 316,640 a------- c:\windows\WMSysPr9.prx 2010-02-07 11:47 <DIR> --d----- c:\windows\peernet 2010-02-07 11:47 <DIR> --d----- c:\windows\provisioning 2010-02-07 11:46 <DIR> --d----- c:\windows\ServicePackFiles 2010-02-07 11:45 26,144 a------- c:\windows\system32\spupdsvc.exe 2010-02-07 11:44 <DIR> --d----- c:\windows\EHome 2010-02-07 11:41 11,264 -------- c:\windows\system32\spnpinst.exe 2010-02-07 11:41 7,208 -------- c:\windows\system32\secupd.sig 2010-02-07 11:41 4,569 -------- c:\windows\system32\secupd.dat 2010-02-07 11:35 <DIR> --ds---- c:\windows\system32\Microsoft 2010-02-07 11:29 <DIR> --d----- c:\windows\system32\bits 2010-02-07 11:29 438,784 a------- c:\windows\system32\xpob2res.dll 2010-02-07 11:29 354,816 a------- c:\windows\system32\winhttp.dll 2010-02-07 11:29 18,944 a------- c:\windows\system32\qmgrprxy.dll 2010-02-07 11:29 8,192 -------- c:\windows\system32\bitsprx2.dll 2010-02-07 11:29 7,168 -------- c:\windows\system32\bitsprx3.dll 2010-02-07 11:28 217,816 a------- c:\windows\system32\wuaucpl.cpl 2010-02-07 11:28 21,728 a------- c:\windows\system32\wucltui.dll.mui 2010-02-07 11:28 17,632 a------- c:\windows\system32\wuaueng.dll.mui 2010-02-07 11:28 15,072 a------- c:\windows\system32\wuaucpl.cpl.mui 2010-02-07 11:28 15,064 a------- c:\windows\system32\wuapi.dll.mui 2010-02-07 11:27 <DIR> --dsh--- c:\documents and settings\dav34\UserData 2010-02-07 11:27 12,980 a------- c:\windows\system32\wpa.bak 2010-02-07 11:16 22 a------- c:\windows\system32\ati64hlp.stb 2010-02-07 11:12 118,656 a----r-- c:\windows\system32\drivers\Rtnicxp.sys 2010-02-07 11:12 73,728 a----r-- c:\windows\system32\RtNicProp32.dll 2010-02-07 11:12 <DIR> --d----- c:\program files\TRENDware International, Inc 2010-02-07 11:04 516,096 -------- c:\windows\system32\ati2sgag.exe 2010-02-07 11:04 290,816 a----r-- c:\windows\system32\atiiiexx.dll 2010-02-07 11:04 <DIR> --d----- c:\program files\ATI Technologies 2010-02-07 10:28 <DIR> --d----- c:\program files\Realtek Sound Manager 2010-02-07 10:28 <DIR> --d----- c:\program files\AvRack 2010-02-07 10:27 131,072 a----r-- c:\windows\system32\e1000msg.dll 2010-02-07 10:27 118,784 a----r-- c:\windows\system32\Prounstl.exe 2010-02-07 10:27 24,064 a----r-- c:\windows\system32\IntelNic.dll 2010-02-07 10:27 2,725 a----r-- c:\windows\system32\e1000325.din 2010-02-07 10:27 125,952 a----r-- c:\windows\system32\drivers\e1000325.sys 2010-02-07 10:27 <DIR> --d----- c:\program files\Gigabyte 2010-02-07 10:27 306,688 a------- c:\windows\IsUninst.exe 2010-02-07 10:19 <DIR> --dsh--- c:\windows\Installer 2010-02-07 10:19 <DIR> --d----- c:\documents and settings\DAV34 2010-02-07 10:08 8,192 a------- c:\windows\REGLOCS.OLD 2010-02-07 10:06 1,875,968 ac------ c:\windows\system32\dllcache\msir3jp.lex 2010-02-07 10:05 <DIR> --dsh--- c:\documents and settings\all users\DRM 2010-02-07 10:04 <DIR> --d----- c:\program files\common files\MSSoap 2010-02-07 10:03 <DIR> --d-h--- c:\program files\WindowsUpdate 2010-02-07 10:03 <DIR> --d----- c:\program files\Online Services 2010-02-07 10:03 <DIR> --d----- c:\program files\Messenger 2010-02-07 10:03 <DIR> --d----- c:\program files\MSN Gaming Zone 2010-02-07 10:03 <DIR> --d----- c:\program files\Windows NT 2010-02-07 03:55 <DIR> --d--r-- c:\documents and settings\all users\Documents 2010-02-07 03:47 <DIR> --d----- c:\program files\common files\ODBC 2010-02-07 03:47 <DIR> --d----- c:\program files\common files\SpeechEngines ==================== Find3M ==================== 2010-02-07 12:45 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat 2010-02-07 10:03 21,640 a------- c:\windows\system32\emptyregdb.dat 2009-12-21 23:35 81,920 -------- c:\windows\system32\ieencode.dll 2009-12-21 13:14 916,480 a------- c:\windows\system32\wininet.dll 2009-11-21 09:51 471,552 a------- c:\windows\apppatch\aclayers.dll ============= FINISH: 10:17:13.96 =============== Hope I did this as stated. This post has been edited by DA22: Feb 9 2010, 05:51 PM |
|
|
|
DA22 [Resolved] Am I clean Feb 9 2010, 11:10 AM
LDTate DO NOT use any TOOLS such as Combofix, Vundofix, o... Feb 9 2010, 06:17 PM
DA22 LDTate, thank you for your advice. I am glad it do... Feb 9 2010, 07:44 PM
LDTate Your question would be more suited for one of the ... Feb 9 2010, 07:49 PM
DA22 LDTate, I thank you for your knowledgeable explana... Feb 10 2010, 07:53 AM
DA22 Ok, I see. I am logged in.
Logfile of Trend Micro ... Feb 10 2010, 08:10 AM
LDTate All I can tell you is your computer looks free of ... Feb 10 2010, 08:09 PM
DA22 LDTate, I thank you for all your input and time an... Feb 11 2010, 08:13 AM
LDTate In IE click on Tools > Internet Options and cli... Feb 11 2010, 11:21 AM
DA22 LDTate, again I do appreciate your help, but it is... Feb 11 2010, 12:40 PM
LDTate You could start a new topic in our Windows Forum a... Feb 11 2010, 06:35 PM
DA22 LDTate, I feel like I got my old machines back. I ... Feb 12 2010, 06:55 AM
LDTate QUOTE Should I ever accept any of the connections ... Feb 12 2010, 04:32 PM
DA22 LDTate, thank you again. I still have not heard an... Feb 12 2010, 04:50 PM
DA22 LDTate, , I finally got Win 7 Pro to not have any ... Feb 15 2010, 08:18 PM
LDTate You're more then welcome.
Glad we were able t... Feb 16 2010, 03:48 PM
LDTate Since this issue appears to be resolved ... this T... Feb 16 2010, 03:48 PM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
15 | tiancheng | 480 | Yesterday, 06:46 AM Last post by: Blade81 |
|||
![]() |
15 | Angel2121 | 496 | Yesterday, 05:46 AM Last post by: jpshortstuff |
|||
![]() |
16 | jester421 | 359 | 20th March 2010 - 09:18 AM Last post by: CatByte |
|||
![]() |
6 | ROOFIE(MTL) | 111 | 20th March 2010 - 06:42 AM Last post by: CatByte |
|||
|
Time is now: 22nd March 2010 - 05:49 AM |